Executive brief
A vulnerability in the Android Framework could allow a local user to view images belonging to other users on the same device. This issue stems from how the system validates input in multiple locations. An attacker could exploit this to gain unauthorized access to private photos or media, though it requires some level of user interaction to succeed.
Technical details
An improper input validation vulnerability exists in multiple locations within the Android Framework component. A local attacker can exploit this flaw to bypass user isolation boundaries and reveal images across different user profiles. The vulnerability is classified as Elevation of Privilege (EoP) because it allows access to data that should be restricted to other user contexts. Exploitation requires user interaction but does not require additional execution privileges. Google has addressed this in the June 2026 Android Security Bulletin with patches for Android versions 14, 15, 16, and 16-qpr2.
Affected products
- Google Android Framework 14, 15, 16, 16-qpr2
Timeline
- 2026-06-01: advisory: Published in the June 2026 Android Security Bulletin
- 2026-06-01: disclosed: CVE published to NVD dataset